DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105643: CVE-2026-105643: Stored Cross-Site Scripting and Isolation Bypass in Ghost CMS

CVE-2026-105643: Stored Cross-Site Scripting and Isolation Bypass in Ghost CMS

Vulnerability ID: CVE-2026-105643
CVSS Score: 7.3
Published: 2026-10-07

Stored Cross-Site Scripting (XSS) and origin isolation bypass vulnerability in Ghost CMS versions 6.34.0 through 6.66.1 allows low-privileged staff users to execute arbitrary JavaScript in the context of an administrator session via crafted embed cards.

TL;DR

A vulnerability in Ghost CMS's Lexical-based editor allows low-privileged staff members to inject malicious script payloads via embed cards. When an administrator views the post in the editor, the script executes on the same origin as the administrative panel, enabling full session hijacking. The issue is resolved in version 6.67.0 by isolating embed previews under a separate origin.


Technical Details

  • CWE ID: CWE-79, CWE-653
  • Attack Vector: Network
  • CVSS Score: 7.3
  • EPSS Score: 0.00271
  • Impact: High (Complete Session Compromise)
  • Exploit Status: None (No public PoC)
  • KEV Status: Not Listed

Affected Systems

  • Ghost Content Management System
  • Ghost: >= 6.34.0, < 6.67.0 (Fixed in: 6.67.0)

Code Analysis

Commit: 4cb7e79

Release candidate packages prepared and code-base version bumps executed. Upgraded koenig-lexical to version 1.11.0.

Mitigation Strategies

  • Upgrade Ghost to version 6.67.0 or higher immediately.
  • Ensure that security.embedPreviewUrl configuration option is left at its secure default value.
  • Limit authoring privileges to trusted staff members to reduce the threat vector.

Remediation Steps:

  1. Log in to the host server running the Ghost instance.
  2. Run the command 'ghost update' or use your deployment pipeline to update to version 6.67.0.
  3. Verify in the config file that security.embedPreviewUrl is not customized to load previews on the same origin.
  4. Audit draft database entries for potential script tags using the provided SQL queries.

References


Read the full report for CVE-2026-105643 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)